goodaccess

MEDIUM
maintainer goddard 0 votes scanned 2026-10-06 00:13:36.889724
View on AUR
Why flagged

Downloads a prebuilt binary .deb from a CDN redirect URL (link.goodaccess.com) with SKIP'd checksum, making it unverifiable and trivially swappable; however the domain appears to be the official GoodAccess vendor infrastructure, which reduces but does not eliminate the risk.

Triggered rules

Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:10 source=("goodaccess_4.7.2-1_amd64.deb::https://link.goodaccess.com/download-linux-deb")
Medium AI review llm_review

An AI model (anthropic/claude-sonnet-4.6) reviewed this and agrees it is MEDIUM (confidence 75%): Downloads a prebuilt binary .deb from a CDN redirect URL (link.goodaccess.com) with SKIP'd checksum, making it unverifiable and trivially swappable; however the domain appears to be the official GoodAccess vendor infrastructure, which reduces but does not eliminate the risk.

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Your Name <your@email.com>
2pkgname="goodaccess"
3pkgver="4.7.2"
4pkgrel="1"
5pkgdesc="GoodAccess client for Linux (converted from .deb)"
6arch=('x86_64')
7url="https://goodaccess.com"
8license=('custom')
9depends=('glibc' 'libstdc++5')
10source=("goodaccess_4.7.2-1_amd64.deb::https://link.goodaccess.com/download-linux-deb")
11noextract=("goodaccess_4.7.2-1_amd64.deb")
12sha256sums=('SKIP')
13
14pkgver() {
15 local ver=$(curl -sL "https://goodaccess-storage.b-cdn.net/applications/prod/linux/repos/deb/dists/stable/main/binary-amd64/Packages" | grep "^Version:" | head -n1 | cut -d' ' -f2)
16 echo ${ver%-*}
17}
18
19package() {
20 local deb_file="goodaccess_4.7.2-1_amd64.deb"
21 local data_tar=$(ar t "${srcdir}/${deb_file}" | grep "^data.tar" | head -n1)
22 bsdtar -O -xf "${srcdir}/${deb_file}" "$data_tar" | bsdtar -C "${pkgdir}" -xf -
23}
24

Scan history

Scanned at (UTC)SeverityRules
2026-10-06 00:13:36 Medium 2
2026-10-05 00:08:03 Medium 2
2026-10-04 00:18:08 Medium 2
2026-10-03 00:23:04 Medium 2
2026-10-02 00:00:32 Medium 2
2026-10-01 00:02:06 Medium 2
2026-09-30 00:20:07 Medium 2
2026-09-29 00:07:46 Medium 2
2026-09-28 00:28:32 Medium 2
2026-09-27 00:07:07 Medium 2
2026-09-26 00:12:15 Medium 2
2026-09-25 00:03:36 Medium 2
2026-09-24 00:24:14 Medium 2
2026-09-23 00:28:13 Medium 2
2026-09-22 00:15:14 Medium 2
2026-09-21 00:26:32 Medium 2
2026-09-20 00:25:31 Medium 2
2026-09-19 00:25:36 Medium 2
2026-09-18 00:17:11 Medium 2
2026-09-17 00:27:14 Medium 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion